Docs
Console

Audit log

Every signal, check, approval and action, append-only, hash-chained and signed.

Audit log shows every event 3AM recorded, newest first. Filter by type (episode, signal, check, decision, approval, action, outcome, model, config, connector, system, human), search reasons and data, or enter an incident id to see only that incident. Open a row for the full record.

The badge at the top shows the result of verifying the whole log: ✓ verified · N events · N segments, or tampering detected.

What makes it tamper-evident

  • Each event includes the hash of the one before it, so the events form a chain.
  • The log is split into segments, and each closed segment is signed with the install's key.
  • Verification recomputes every hash and checks every signature: an edited, deleted, inserted or reordered event is detected.
  • Secrets and card numbers are redacted before anything is written. Model calls store a hash of the full prompt and a redacted copy.

Verify from the command line at any time:

podman exec 3am-core /opt/3am/3am-core ledger-verify /var/lib/3am/ledger

The command exits 1 if anything was altered.

On this page